URLhaus Database

You are currently viewing the URLhaus database entry for http://gons14fc.top/build.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2729647
URL: http://gons14fc.top/build.exe
URL Status:Offline
Host: gons14fc.top
Date added:2023-11-10 09:23:11 UTC
Last online:2023-11-10 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-11-10 13:02:06 UTC to cloud-abuse{at}yandex-team[dot]ru)
Takedown time:1 day, 20 hours, 39 minutes Poor (down since 2023-11-12 06:03:22 UTC)
Tags:dropped-by-PrivateLoader emotet link heodo link MarsStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-12n/aexe 5d5ddfc804f8c8a1fc122ade20e48f50c5cbc56ce7439928215c6f360cfa94een/a Heodo
2023-11-11n/aexe 89c79691ee5523601062790836ab72546f934b75c86ae8e97036fd8c589bda00Virustotal results 38.03% Heodo
2023-11-11n/aexe 041aea2453881afc10241032f0ec0e712567af6572bb7a03535000035942d415Virustotal results 38.89% Heodo
2023-11-11n/aexe 023d20cf348044b1596ab0aa458ae49ce02a47eeb2c7bdda5bfa3354b7319ea5Virustotal results 38.89%Heodo
2023-11-10n/aexe 132b4fe0337a790a4f0e00cd6cc02bd865b02519c76054b58a448e72f1afc8deVirustotal results 40.28%Heodo
2023-11-10n/aexe bd442895a10c0b01daa543174c33d31ed05b905af2c6f5ab56c709893b1eed34Virustotal results 41.67%Heodo
2023-11-10n/aexe 214946b987ad69fa46f1d27ab35026b856a4fcd2abd46b0b5ba86dc71be58d89Virustotal results 43.06%Heodo
2023-11-10n/aexe f3d65482462d9d8b67e0385c477383ea1fe05e7a5f80e825bf4e6546ddf33602Virustotal results 38.89%MarsStealer